The European Data Protection Board (EDPB) is the independent EU body responsible for ensuring the GDPR is applied consistently across all 27 EU member states plus Norway, Iceland, and Liechtenstein. It was established on 25 May 2018, the day the GDPR took effect, replacing the earlier Article 29 Working Party.
The EDPB doesn’t enforce GDPR against individual companies directly — national data protection authorities (DPAs) do that — but it issues the guidelines those authorities rely on, resolves disputes between DPAs on cross-border cases through binding decisions, and increasingly shapes how GDPR interacts with the AI Act, the DSA, and the DMA.
If your compliance programme cites “GDPR guidance” without being specific about which body issued it, there’s a good chance it’s EDPB guidance you’re actually relying on.
What Is the EDPB?
The EDPB is an independent European body with its own legal personality, established under Chapter VII of the GDPR (Articles 68 to 76). It came into existence on 25 May 2018, replacing the Article 29 Working Party, the informal advisory body that had performed a similar function under the pre-GDPR 1995 Data Protection Directive.
Unlike its predecessor, the EDPB has a formal legal basis, the power to issue binding decisions in specific circumstances, and a permanent secretariat based in Brussels, provided by the European Data Protection Supervisor (EDPS).
The Board’s primary role, set out in Article 70 GDPR, is to ensure the consistent application of the GDPR and the Law Enforcement Directive across the European Economic Area. It does this without itself acting as a regulator of individual companies — that job stays with the national supervisory authorities.
Key EDPB Terms Defined
| Term | Definition |
|---|---|
| EDPB | The European Data Protection Board — the EU body ensuring consistent GDPR application across the EEA, composed of the heads of national DPAs plus the EDPS |
| EDPS | The European Data Protection Supervisor — a separate body that supervises EU institutions’ own data processing and provides the EDPB’s secretariat, distinct from the EDPB itself |
| Supervisory Authority (SA / DPA) | The national data protection authority in each EU/EEA member state — the body that actually investigates, audits, and fines companies for GDPR non-compliance |
| One-stop-shop mechanism | The GDPR system under which a company’s “lead” DPA, based on its main EU establishment, coordinates enforcement for cross-border processing, with other “concerned” DPAs involved where their residents are affected |
| Consistency mechanism | The Article 63–67 process requiring DPAs to cooperate and, in specified cases, submit draft decisions to the EDPB before they’re finalised, to prevent divergent outcomes across member states |
| Binding decision | An EDPB decision under Article 65, issued when DPAs cannot reach consensus in a cross-border case, which the lead DPA is legally required to follow in its final decision |
What the EDPB Actually Does
| Task | What it involves | Legal basis |
|---|---|---|
| Issuing guidelines and recommendations | Publishing interpretive guidance on GDPR concepts — legitimate interest, data transfers, dark patterns, AI training data, and dozens of other topics — that DPAs and companies use to interpret the Regulation in practice | Article 70(1) |
| Advising the European Commission | Providing opinions on Commission proposals, adequacy decisions for third countries, and the data protection implications of other EU legislation | Article 70(1)(e)-(s) |
| Ensuring consistent application | Reviewing draft decisions DPAs submit under the consistency mechanism, and issuing opinions where a DPA’s proposed decision might create inconsistent outcomes across the EEA | Articles 63–64 |
| Resolving cross-border disputes | Issuing binding decisions when DPAs involved in a cross-border case cannot agree, which the lead DPA must then follow | Article 65 |
| Coordinating enforcement | Running the one-stop-shop mechanism and coordinated enforcement framework so a company facing a cross-border complaint deals with one lead authority rather than 30 separately | Article 60 |
| International cooperation | Contributing to adequacy assessments and engaging with data protection authorities outside the EEA | Article 70(1)(t)-(v) |
EDPB vs National DPAs vs EDPS: Who Does What
This is the most common point of confusion, and it matters for anyone trying to work out who actually has authority over their organisation.
| Body | Enforces GDPR directly against companies? | Issues fines? | Issues interpretive guidance? |
|---|---|---|---|
| EDPB | No | No — not against companies | Yes — this is its central function |
| National DPA (e.g. CNIL, Garante, Datenschutzbehörde) | Yes | Yes | Yes, at national level, but must follow EDPB guidance and binding decisions |
| EDPS | Only over EU institutions and bodies, not private companies | Only over EU institutions | Yes, on EU-institution processing specifically |
If your company receives an investigation notice, an audit request, or a fine, it comes from a national DPA, not the EDPB directly. The EDPB’s influence is upstream of that: it shapes what the DPA is likely to conclude, and in cross-border cases where DPAs disagree, its binding decision determines the outcome the lead DPA must issue.
How EDPB Guidance Actually Affects Your Compliance
EDPB guidelines are not law in the way the GDPR articles themselves are. A company cannot be fined for violating an EDPB guideline as such. In practice, this distinction matters less than it sounds, for two reasons.
First, national DPAs treat EDPB guidelines as the authoritative interpretation of ambiguous GDPR provisions, and enforcement decisions routinely cite them directly. Ignoring an EDPB guideline because it isn’t technically binding is a weak position to defend in front of the DPA that has adopted it as its own interpretive standard.
Second, where a cross-border case reaches the Article 65 dispute resolution stage, the EDPB’s decision stops being “guidance” and becomes binding on the lead DPA by law. A company operating across multiple member states is more likely to encounter this mechanism than a purely domestic one, since cross-border processing is exactly what triggers it.
EDPB and AI: The Overlap Nobody Reads Closely Enough
The EDPB’s 2024–2025 and 2026–2027 work programmes both name cross-regulatory guidance as a priority, specifically covering the interplay between GDPR and the AI Act, the DSA, and the DMA. The Board has already issued a formal opinion addressing when and how AI models trained on personal data engage GDPR obligations, covering questions like whether a trained model itself constitutes personal data and what anonymisation standard applies to training datasets.
For an AI company, this matters because the AI Act’s own data governance requirements and GDPR’s lawful-basis and data-minimisation requirements are not the same test, and the EDPB is the body actively working out where they converge and where they diverge — ahead of, and sometimes instead of, the AI Office doing the same work from the AI Act side.
Current Work Programme
The EDPB adopted its Work Programme 2026–2027 on 11 February 2026, the second instalment implementing its Strategy 2024–2027. Alongside continued guidance on cross-regulatory interplay, the Board is developing a set of standard EU templates aimed specifically at reducing compliance burden for smaller organisations:
- Data breach notification templates
- Data Protection Impact Assessment templates
- Legitimate interest assessment templates
- Records of processing templates
- Privacy notice templates
These are worth watching directly, since a company that builds its own documentation ahead of the EDPB template release risks having to rework it once the standard version lands.
How Grecta Can Help
EDPB guidance changes faster than most compliance teams can track, and it increasingly determines how GDPR interacts with the AI Act, the DSA, and the Data Act on the same product. Grecta’s compliance engine tracks EDPB guidelines and Article 65 decisions alongside the underlying regulations they interpret, so a change in EDPB guidance shows up as a change in your product’s compliance status, not as a document you have to notice on your own.
Key Facts
| Item | Detail |
|---|---|
| Established | 25 May 2018, the date the GDPR took effect |
| Predecessor body | Article 29 Working Party |
| Legal basis | GDPR Articles 68–76 |
| Membership | Heads of the supervisory authorities of 27 EU member states plus Norway, Iceland, and Liechtenstein, plus the EDPS; a non-voting European Commission representative also attends |
| Current chair | Anu Talus |
| Current deputy chairs | Irene Loizidou Nicolaidou, Zdravko Vukić |
| Secretariat | Based in Brussels, provided by the EDPS |
| Latest work programme | 2026–2027, adopted 11 February 2026 |
What is the European Data Protection Board?
The EDPB is the independent EU body responsible for ensuring the GDPR and the Law Enforcement Directive are applied consistently across the European Economic Area. It was established on 25 May 2018 and is composed of the heads of the national data protection authorities of the EU member states plus Norway, Iceland, and Liechtenstein, along with the European Data Protection Supervisor.
Is the EDPB the same as a national data protection authority?
No. The EDPB is a coordinating and guidance-issuing body at EU level. It does not investigate or fine individual companies directly. That authority sits with each country’s national DPA — the CNIL in France, the Garante in Italy, and so on — which enforces GDPR at the national and cross-border level, informed by EDPB guidance.
Can the EDPB fine a company?
Not directly. The EDPB does not have the power to issue fines against private companies. Fines are issued by national DPAs. Where a cross-border case reaches Article 65 dispute resolution, the EDPB’s binding decision determines what the lead DPA must decide, but the DPA itself issues the fine.
Is EDPB guidance legally binding?
Guidelines, recommendations, and best practices issued under Article 70 are not binding law in themselves. Article 65 decisions, issued to resolve disagreements between DPAs in cross-border cases, are binding on the lead DPA by law. In practice, national DPAs treat Article 70 guidance as authoritative and cite it routinely in enforcement decisions, so the practical distinction is smaller than the formal one.
What is the difference between the EDPB and the EDPS?
The EDPB ensures consistent GDPR application across all controllers and processors in the EEA and is composed of national DPA heads. The EDPS is a separate, single office that supervises data processing by EU institutions and bodies specifically — the European Commission, Parliament, and similar bodies — not private companies. The EDPS also provides the EDPB’s secretariat, which is a common source of the confusion between the two.
What is the one-stop-shop mechanism and how does the EDPB relate to it?
The one-stop-shop mechanism lets a company with cross-border EU processing deal primarily with a single “lead” DPA, based on its main EU establishment, rather than every DPA in every member state where it has users. The EDPB doesn’t run this mechanism day to day, but it resolves disputes when the lead DPA and other “concerned” DPAs cannot agree on the outcome.
Does the EDPB do anything relevant to the AI Act?
Yes. The EDPB’s 2024–2025 and 2026–2027 work programmes both prioritise guidance on how GDPR interacts with the AI Act, the DSA, and the DMA. It has issued a formal opinion on how GDPR applies to AI models trained on personal data, including questions of anonymisation and whether a trained model itself constitutes personal data.
Who is on the EDPB?
The heads of the national supervisory authorities of the 27 EU member states, plus Norway, Iceland, and Liechtenstein, together with the European Data Protection Supervisor. A representative of the European Commission attends but does not have voting rights.
Where can I find official EDPB guidelines?
Directly on the EDPB’s own website, which publishes all adopted guidelines, recommendations, opinions, and binding decisions. Guidance summarised on third-party sites, including this one, should be checked against the original text before being relied on for a specific compliance decision.